VYPR
Vendor

Softstack

Products
3
CVEs
4
Across products
4
Status
Private

Products

3

Recent CVEs

4
  • CVE-2023-41331CriSep 12, 2023
    risk 0.64cvss 9.8epss 0.01

    SOFARPC is a Java RPC framework. Versions prior to 5.11.0 are vulnerable to remote command execution. Through a carefully crafted payload, an attacker can achieve JNDI injection or system command execution. In the default configuration of the SOFARPC framework, a blacklist is…

  • CVE-2024-46983CriSep 19, 2024
    risk 0.57cvss 9.8epss 0.01

    sofa-hessian is an internal improved version of Hessian3/4 powered by Ant Group CO., Ltd. The SOFA Hessian protocol uses a blacklist mechanism to restrict deserialization of potentially dangerous classes for security protection. But there is a gadget chain that can bypass the…

  • CVE-2024-23636CriJan 23, 2024
    risk 0.57cvss 9.8epss 0.01

    SOFARPC is a Java RPC framework. SOFARPC defaults to using the SOFA Hessian protocol to deserialize received data, while the SOFA Hessian protocol uses a blacklist mechanism to restrict deserialization of potentially dangerous classes for security protection. But, prior to…

  • CVE-2005-2857Sep 8, 2005
    risk 0.03cvss epss 0.03

    Free SMTP Server 2.2 allows remote attackers to use the server as an open mail relay (spam proxy).